The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

HTTP Response Decompression

Prev Next

HTTP response is commonly compressed in gzip or deflate format to improve performance. In gzip compression format, the web servers replace the common text in the HTTP response traffic by an arbitrary placeholder to reduce the file size. Whereas in deflate compression format, the web servers encode the HTTP response traffic content using LZ77 and Huffman encoding algorithms. The web servers then replace common text in the encoded HTTP response traffic by an arbitrary placeholder to attain better compression. Therefore, these formats reduce transfer time and bandwidth consumption. However, attackers use it to evade detection of malicious payload. Enabling this option instructs the Sensor to decompress compressed HTTP response traffic for inspection.

When HTTP response decompression is enabled, the Sensor inspects the HTTP response traffic for compressed data. The compressed data identified are categorized as gzip or deflate based on their compression mechanism. After categorization, the HTTP response traffic is decompressed using the decompression engine. The decompressed HTTP response traffic is further inspected for anomalies using the signature set. Post inspection, the response actions configured in the inspection options are triggered.

Points for consideration:

  • HTTP Response Decompression is disabled by default.

  • To enable HTTP Response Decompression, HTTP response traffic scanning should be enabled.

  • HTTP Response Decompression is supported for gzip and deflate compressed files only.

  • Advanced malware inspection of decompressed files is not supported.

  • This feature is supported on NS-series and Virtual IPS Sensors.